By Moti Shay Ā· Israel
Phishy started with one question that kept coming back: "Moti, I got a strange message, can I click the link? Is it legit?" My parents asked me that every few days. My name is Moti Shay, and I sign this page with my own name because you deserve to know who you are pasting a suspicious message to.
I answered them every time. But at some point I realised my answer solved nothing, because I am not always available, and they do not always ask. Sometimes the message arrives while I am at work, and they simply tap it. And then feel too embarrassed to mention it.
That is not their failing. "Unpaid toll on your account." "Your parcel is waiting for a customs fee." "Unusual activity detected on your account." These messages are written by professionals and sent to hundreds of thousands of people. The real problem is that there is no good way to check: on a phone you cannot hover over a link. The only way to "see" where it leads is to tap it, which means visiting the malicious page.
And the scammers know this precisely. They are not spraying in every direction, they are aiming. These messages are built around people who did not grow up with the internet: plain language, a familiar brand, an amount too small to be worth verifying, and urgency that leaves no room to think. Someone who does not know that a sender name can be forged, and that a shortened link can lead anywhere, simply is not given a fair chance. That is not naivety on their part; it is an entire industry built to face them. Which is why phishing succeeds most of all against our parents and grandparents.
So I built the tool I wanted to hand them. Paste the message, get an answer, and your phone never touches the link.
That is why Family Mode is the heart of the app rather than an add-on. I did not want my parents to have to ask me every single time, I wanted them to know on their own. And children too: they receive exactly the same messages, and they are even less likely to stop and ask anyone before they tap.
The message itself is never stored. Not in a database, not in a log, not by me. What is counted, fully anonymously: the date, the verdict, a label for the organisation the message impersonated, the interface language and the visitorās country. Not stored: the message text, the link inside it, IP address, name, phone number or any other identifier. No row in that data can be traced back to a person, not even by me.
That anonymous count is what feeds the Scam Index, a live picture of who scammers impersonate most, open to everyone.
Because a tool that asks for money the moment somebody frightened looks at a suspicious message will not do its job. No ads in the checker, no data sales, no signup. The app is free too. I build it in my own time, and if it grows I will look for funding that does not come at the expense of the people using it.
I am not a security company and not a government body. Phishy is a first-aid layer, not a substitute for caution and not a guarantee. If you have been hit, report it to your national cybercrime line and block the card directly with your card issuer, using the number printed on the back of the card. In Israel: dial 119, free, 24/7.
I am available for comment, technical background or a data breakdown for a story, in English or Hebrew. Topics I can speak to concretely:
The Scam Index is free to cite under CC BY 4.0 with credit and a link. For a custom breakdown (by month or scam type), just write to me.
š§ support@phishyapp.com, I answer every email.